Official Red Hat NPM accounts have been compromised and used to push a malicious worm that spreads from machine to machine, ...
Your Monday cybersecurity recap covers the latest digital threats, exposed weaknesses, active attacks, and security stories ...
Microsoft has identified an active supply chain attack targeting the npm package ecosystem. On May 28, 2026, a single threat actor operating under the newly created maintainer alias vpmdhaj (a39155771 ...
Cybercriminals used the Glassworm botnet to infect open source software projects with malware, and in turn hack the ...
The tool operates with broad system privileges and autonomous execution capabilities, demonstrating how natural language can ...
An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances. Designed as an alternative to GitHub ...
Two months after Rapid7 discovered the hole in the Git service, the project maintainer has yet to patch the bug.
CrowdStrike, Google and the Shadowserver Foundation worked together to take down a botnet that poisoned over 300 GitHub ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results